CompTIA PenTest+ Practice Test 3

CompTIA PenTest+ Practice Test

1 / 10

A pen test targets a web app with strict data privacy laws. Which scoping step ensures legal compliance?

2 / 10

You’re reviewing a C program with user input. Which line poses a buffer overflow risk?

3 / 10

A client needs a report for auditors showing compliance gaps. Which section should detail regulatory violations?

4 / 10

You’re targeting a Linux server with a vulnerable sudo configuration. Which command escalates privileges?

5 / 10

A target exposes port 3389 (RDP). Which command checks for weak RDP configurations?

6 / 10

You’re auditing a JavaScript file for security flaws. Which tool identifies potential DOM-based XSS issues?

7 / 10

A pen test reveals multiple vulnerabilities. Which report element prioritizes fixes based on risk?

8 / 10

A web server allows file uploads without validation. Which payload tests for remote code execution (RCE)?

9 / 10

You’re performing OSINT on a target company. Which tool extracts employee email addresses from public sources?

10 / 10

A client requests a pen test but mandates third-party approval for cloud-hosted systems. Which document should address this requirement?

Your score is

The average score is 0%

0%